Courseiva

CHFI Mobile and Malware Forensics Practice Question

Which Android file system location is MOST likely to contain user-installed app data, preferences, and cached information?

⚠ Common exam trap

EC-Council often tests the misconception that user-installed app data is stored on the SD card (/mnt/sdcard/) because users commonly see app files there, but in Android's security model, private app data is strictly kept in /data/data/ and not on external storage.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

/data/data/

The /data/data/ directory on Android devices stores application-specific data for user-installed apps, including preferences (shared preferences XML files), databases, and cached information. This location is part of the internal storage partition and is sandboxed per app, ensuring that each app can only access its own data directory. It is the primary repository for runtime app data, making it the most relevant for forensic analysis of user-installed app artifacts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    /vendor/

    Why it's wrong here

    On Android, /vendor is a read-only partition containing proprietary binary blobs, hardware abstraction layer (HAL) libraries, and device-specific components supplied by the SoC manufacturer. It is mounted early in boot to support kernel-level hardware interactions, and it holds no per-app or per-user data such as databases or preferences. While relevant for firmware analysis, it cannot contain app-specific user data for forensic recovery.

  • ✓

    /data/data/

    Why this is correct

    The /data/data directory (accessible as /data/user/0 on modern Android) is the standard, sandboxed root for each installed application's private data, including SQLite databases, SharedPreferences, cache files, and native libraries. Access is protected by Linux UID permissions—each app runs with a unique UID—so only the app itself and the root user can read these files. For forensic examiners, this is the primary source for recovering user app data such as chat logs, browser history, and app-generated artifacts.

  • ✗

    /system/

    Why it's wrong here

    The /system partition contains the core Android OS framework, including framework classes, standard system applications, and the init scripts that are mounted read-only to preserve system integrity. Its contents are identical across devices with the same build, and even system apps store their runtime data in /data/ rather than under /system. Therefore, /system holds no per-installation or user-specific app data and is not a target for app data extraction.

  • ✗

    /mnt/sdcard/

    Why it's wrong here

    The /mnt/sdcard path is a legacy mount point for the emulated external storage (now /storage/emulated/0), which is a FUSE-based shared filesystem designed for user media and common documents, not for private app data. While apps may intentionally place exported files here (like downloads or photos), the data is not sandboxed and is readable by multiple apps and the user, so it lacks the integrity and ownership of /data/data. App-private databases, preferences, and internal caches are never stored on this mount, making it incorrect for this forensic question.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.